yybd

Cross Repo Guards — AI skill for Claude Code

AI community

Cross-repo guards for AI coding agents.

How to install Cross Repo Guards

This entry records only its repository, not the path inside it, so there is no exact command to give. Open yybd/cross-repo-guards and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Cross Repo Guards does

Cross-repo guards for AI coding agents. Refuses a blind write or a sweeping commit into a repo the session is not standing in, and closes every place it left open. A Claude Code plugin marketplace: grove.

Alternatives in AI

  • Skills Manage — Desktop app to manage AI coding agent skills across Claude Code, Cursor, Gemini CLI, Codex, and 20+ platforms 2.2k ★
  • Firm — Convene your standing AI staff — memos on every beat, a board session without you, minutes with dissent preser 1.3k ★
  • Internal Safety Collapse — We built an adversarial codespace setup 1.2k ★

README

*English · [עברית](README.he.md)*

Grove (Cross-Repo Guards)

**The safety and orchestration layer for AI agents in multi-repo environments.**

An AI agent (like Claude Code) is a brilliant tool when operating within a single project folder (Repository). However, in the real world, tasks cross boundaries: shipping a feature requires a code change (App), a data schema update (Hub), and editing a marketing page (Web). The moment the agent "reaches out" to a foreign directory, it loses touch with reality. Because the `git status` command is limited to its current working directory, the agent might blindly overwrite another developer's open files, push code to the wrong branch, or perform a destructive blind commit.

**Grove was built to solve exactly this.** It is a set of guardrails that run inside the session, at the moment of the tool call: they detect the anomaly, refuse the two actions that cannot be undone, and hand the agent back the picture it was missing so it can correct itself.


The Components: What does Grove do?

The system provides 3 critical solutions:

1. Active Guardrails (The Guard Hooks)

  • Blocking Blind Commits (scope_foreign_commits): If the AI stands in directory A and attempts to run git commit -a in directory B, the system blocks it. Instead of a generic failure, it injects the true state of the foreign directory (including the branch name and open files), instructing the AI to commit only specific files.
  • Honoring Boundaries (honor_ownership): If a file is claimed by another project (via .claude/owns.json), the hook refuses to let the AI edit it, redirecting the agent to the proper location.

2. Smart Contextual Committing (`close.py`)

An agent updating 3 projects simultaneously leaves a trail of changes. Standard Git commands break down here. The script `$GROVE/tools/close.py --commit` reads which files **this specific session** wrote across every directory, and stages only those — never a sweep. What it claim